Solution Overview for Business Users / Version 2506.0
Table Of Contents
Preview-based editing relies on cross-window communication (via the browser
postMessage API) between Studio and the preview rendered by the
preview client. On receiving the handshake message, coremedia.preview.js injects
a script provided by the sender, so the origins that are allowed to drive the preview must be
restricted.
previewclient.studio-url-whitelist[0]=https://studio.example.com previewclient.studio-url-whitelist[1]=https://studio.intranet.example.com:8081
Important
If the whitelist is left empty, the preview accepts cross-window messages from any origin. For security-sensitive deployments you should always configure the Studio origins explicitly.


